BitBucket²ÎÊý×¢ÈëÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-09-23

¡ñÎó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-15000£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º9.8


¡ñÓ°Ïì°æ±¾


version < 5.16.10

6.0.0 <= version < 6.0.10

6.1.0 <= version < 6.1.8

6.2.0 <= version < 6.2.6

6.3.0 <= version < 6.3.5

6.4.0 <= version < 6.4.3

6.5.0 <= version < 6.5.2


¡ñÎó²î¸ÅÊö


Atlassian Bitbucket ServerºÍAtlassian Bitbucket Data Center¶¼ÊǰĴóÀûÑÇAtlassian¹«Ë¾µÄ²úÆ·¡£¡£¡£¡£¡£Atlassian Bitbucket ServerÊÇÒ»¿îGit´úÂëÍйܽâ¾ö¼Æ»®¡£¡£¡£¡£¡£¸Ã¼Æ»®Äܹ»ÖÎÀí²¢Éó²é´úÂ룬£¬£¬£¬£¬£¬¾ßÓвî±ðÊÓͼ¡¢JIRA¼¯³ÉºÍ¹¹½¨¼¯³ÉµÈ¹¦Ð§¡£¡£¡£¡£¡£Atlassian Bitbucket Data CenterÊÇAtlassian BitbucketµÄÊý¾ÝÖÐÐİ汾¡£¡£¡£¡£¡£


¿ËÈÕ£¬£¬£¬£¬£¬£¬Atlassian ¹Ù·½Ðû²¼Á˹ØÓÚAtlassian BitbuckeÎó²îͨ¸æ£¬£¬£¬£¬£¬£¬Atlassian Bitbucket ServerºÍAtlassian Bitbucket Data CenterÖб£´æ×¢ÈëÎó²î£¬£¬£¬£¬£¬£¬ÔÊÐí¹¥»÷ÕßÏòGitÏÂÁî×¢ÈëÌØÁíÍâ²ÎÊý£¬£¬£¬£¬£¬£¬Õâ¿ÉÄܵ¼ÖÂÔ¶³ÌÏÂÁîÖ´ÐС£¡£¡£¡£¡£ÈôÊÇÔ¶³Ì¹¥»÷ÕßÄܹ»»á¼ûBitbucket Server»òBitbucket Data CenterÖеÄGit´æ´¢¿â£¬£¬£¬£¬£¬£¬Ôò¿ÉÒÔʹÓô˲ÎÊý×¢ÈëÎó²î¡£¡£¡£¡£¡£ÈôÊÇΪÏîÄ¿»ò´æ´¢¿âÆôÓÃÁ˹«¹²»á¼û£¬£¬£¬£¬£¬£¬Ôò¹¥»÷Õß¿ÉÒÔÄäÃûʹÓôËÎó²î¡£¡£¡£¡£¡£


¡ñÎó²îÑéÖ¤


ÔÝÎÞPOC¡¢EXP¡£¡£¡£¡£¡£


¡ñÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£º

https://jira.atlassian.com/browse/BSERV-11947


¡ñ²Î¿¼Á´½Ó


https://jira.atlassian.com/browse/BSERV-11947

https://confluence.atlassian.com/bitbucketserver/bitbucket-server-security-advisory-2019-09-18-976762635.html